Portspoof service signature obfuscator (more pain for port scanners)

2012.08.05
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: N/A

The portspoof program is designed to enhance OS security through emulation of legitimate service signatures on otherwise closed ports. It is meant to be a lightweight, fast, portable and secure addition to the any firewall system or security infrastructure. The general goal of the program is to make the port scanning software (Nmap/Unicornscan/etc) process slow and output very difficult to interpret, thus making the attack reconnaissance phase a challenging and bothersome task. Here is an example nmap scan result against system running portspoof: - default scan took about 800s (instead of 20s) - CPU usage was at 0,5% - memory usage was at 0,5% - one legitimate service is running on port in range of 1-65535 - all the rest is fake - portspoof will bind only to one port Check portspoof in action (Live demo - will sometimes hang due to dev. process ): nmap -sV 54.247.124.68 Portspoof is still an early work in progress and although stable and working it will require a lot of additional work (preferably along with a good beverage :)).

References:

http://portspoof.duszynski.eu/en/download/
http://portspoof.duszynski.eu/en/


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top